What happened, when did it happen and which actor was responsible?
Medical Audit
Tamper-evident audit infrastructure for healthcare software.
Build auditability into your product without building the entire audit infrastructure yourself. Medical Audit gives healthcare software vendors a dedicated service for capturing, protecting, investigating, verifying and producing evidence from important application activity.

The problem
Having logs is not the same as having a protected, usable audit record.
Important healthcare software activity often needs to be understood long after it happened. Ordinary application logs are useful for diagnostics, but auditability introduces a different set of questions.
Can investigators find relevant activity without searching raw application logs?
Can the integrity of the protected audit history be checked?
Can relevant records be packaged into usable evidence?
How Medical Audit works
From application activity to verifiable audit evidence.
Medical Audit provides a dedicated auditability layer between your application activity and the people who need to investigate, verify and produce evidence from it.
Capture
Send structured audit events from your application through the Medical Audit API.
Protect
Events are canonicalised, sequenced and cryptographically linked so changes to protected history can be detected.
Investigate
Authorised users can search, filter and inspect audit activity through a dedicated customer experience.
Verify
Integrity information provides a way to check that the protected audit sequence remains internally consistent.
Prove
Generate Evidence Packs that package relevant audit information for review and verification.
Investigate
Find the events that matter.
Search and filter protected audit records to investigate user, system and API activity without digging through raw application logs or querying production databases.
Search audit history
Narrow activity using date and time together with event, actor and entity criteria.
Inspect event context
Review ordered activity with event, actor, entity, sequence and ingestion context.
Dedicated audit experience
Give authorised users a purpose-built investigation interface rather than exposing operational logs or application databases.

Protect & Verify
Make historical changes detectable.
Medical Audit does more than store events. Protected audit records are processed through a deterministic integrity protocol designed to make changes to historical event data detectable.
Structured event data is converted into a deterministic representation.
Events receive an ordered position within the tenant audit history.
Cryptographic hashes link each protected event to the preceding audit state.
The resulting sequence can be checked for integrity inconsistencies.
Evidence Packs
Turn protected audit history into usable evidence.
Evidence Packs provide a controlled way to package relevant audit information for investigation, review and independent integrity verification.
Create
Select the required audit scope and request an Evidence Pack.
Track
Review Evidence Pack history and processing status from the customer portal.
Download
Retrieve the generated evidence for authorised review and verification.
Built for integration
Add an auditability layer to your product.
Medical Audit is designed for healthcare software vendors that need audit capabilities without turning audit infrastructure into another subsystem they have to design, build and operate themselves.
API-first
Applications send structured audit events through a defined ingestion API rather than coupling directly to the underlying storage implementation.
Tenant-aware
Tenant context and separation are built into the platform so audit records remain associated with the correct customer environment.
Managed infrastructure
SebGenesis operates the auditability infrastructure so your engineering team can remain focused on the healthcare product it owns.
Customer Portal
Auditability your customers can actually use.
Medical Audit includes a customer-facing experience for the operational workflows around protected audit data.
Engineering
